Showing posts with label e-commerce. Show all posts
Showing posts with label e-commerce. Show all posts

Tuesday, May 7, 2013

Just when I thought I understood this "e-commerce" stuff ...

... I was looking for clothes on a major retailer's web site.  Scrolling down, I see a bunch of "sponsored links" at the bottom.  For other stores.

For the same items I'm looking for.

For less.

Huh?


Monday, November 7, 2011

Yay! Yet another way to spam!

While buying something online today, I was presented with a popup asking me if I wanted to chat live with a representative about what looked like a loyalty program.  I went ahead and clicked, even though my spidey-sense told me not to.
PhineasTaylor is typing ... 
Hello there!  Thank you for taking a moment to chat with me about the wonderful opportunity of joining buyeverythingthroughus.com.  With buyeverythingthroughus.com, etc., etc.
OK, a little boilerplate to get things going.  Hang on though, there's more
PhineasTaylor is typing ...
Buyeverythingthroughus.com will improve your life in every possible way.  It will make you rich and famous.  It will cure dandruff and halitosis.  Children will love you.  Adults will want to be you.  Your friends will adore you.  Your enemies will envy you and then slink away in shame and fear, etc., etc.
Right ... anything else?
PhineasTaylor is typing ...
This P.T. person sure types a lot.
Buyeverythingthroughus.com will cure hunger.  It will bring about world peace and universal prosperity.  Yankees and Red Sox fans will embrace each other with love in their eyes [well, maybe it didn't go quite that far].
Since this is ostensibly a person typing, it's coming across slowly enough that there's plenty of time to go googling and find out that buyeverythingthroughus.com is about what you'd expect it is.
Knowing all that, what do you say to this exciting opportunity?
I said "No, thank you" and dismissed the chat window.  I couldn't help wondering, though, whether whoever coded this up had the chutzpah to submit a paper on an exciting new "intelligent agent".

Banking on web security

People do care about web security.  There are highly competent full-time professionals in the field.  There are conferences on the subject on a regular basis.  You'll see them in the press -- Experts Meet to Fix Security on the Web.

And yet, in large part because the problems to be solved are hard and involve significant non-techical factors, there is no shortage of things that could stand to be fixed.
  • Authentication is a mess.  For the most part, we have passwords and security questions.  I've griped about this before, multiple times, and I'm sure I'll gripe about it again.
  • Identity is a mess.  Everyone has scads and scads of identities -- logins here, there and everywhere. They can easily get confused ("That wasn't me, that was some other David Hull!").  There's no good way to say two random identities are or aren't the same.  I've griped and speculated about this before, too, and I expect I'll have more to say on that, too.
  • Anonymity is problematic.  Everything you do on the web leaves traces, but unless you're paying extremely close attention you generally don't know exactly what kind, or whether they can be tied to your identity (whatever that is).
  • Network infrastructure is scary.  Https with certificates is widely deployed, and most people probably at least know that some sites are "secured" and some aren't, but many fewer understand (or should need to understand) details like signatures, secure hashes and certificate authorities, or what can fail and what's less likely to.  Did I mention DNS?
  • PCs are scary.  Viruses, rootkits, system crashes ... some platforms are better designed than others, but nothing's perfect.
  • The cloud has its own problems.  Who owns what you put there?  Who's liable if data is lost or compromised?  Who can see what?  Who can see who sees what?
  • Spam is a perennial problem, not helped by any of the above.
I could go on, but if it's so bad -- and it is -- how does it work at all?  People continue to be able to use credit cards both online and in person, people continue to email and text each other all sorts of sensitive information, people continue to turn to the web for all sorts of vital information.  Clearly Bad Things can happen to a person on the web, but just as clearly it's not bad enough often enough to put people off the web entirely.  Far from it.

My guess is that banks have a lot to do with it, at least in the US.  In particular
  • Banks handle liability.  If someone steals your credit or debit card, whether physically or online, you can tell your bank and generally they will make sure you don't have to pay for things you didn't buy.  That's oversimplified, and there are certainly cases where that simple process has turned into a nightmare, but it's still a vital part of getting people to do business confidently online.
  • Bank cards provide a de facto stable identity.  If you're buying something from my web site, I do care who you are (well, I would, and stores in general do seem to care what their customers are up to), but I certainly also care that your payment is going to go through.  To some extent I'm talking to you, but I'm also talking to your bank account.
On the first point, you're not responsible for keeping your bank accounts absolutely safe.  You're responsible for taking reasonable precautions, so that if someone does get hold of your account number and misuses it, they're clearly at fault (the usual "I'm not a lawyer" disclaimer applies here).  Putting the rest of the burden on the banks and legal system is a large part of what keeps the wheels turning.

On the second point, if I shop at store A and store B, it's important that my bank knows that those purchases both come out of my account, and I know that I'm the same person in both cases (at least on a good day).  It's less important that store A and store B know I'm the same person.  There may even be cases where I'd rather they didn't know.

In short, security and identity matter when money is at stake, in which case your accounts serve as your identity and you have legal protections that predate the web.

Security and identity also matter where reputation is at stake, that is in the social realm, be it email, social networks, Twitter or whatever.  The landscape is different there, but it's worth noting that most accounts and identities, including your bank accounts, don't play into that much.  If someone compromises my account at widgetco.com, they might be able to have a truckload of widgets sent to my address at my expense, but they won't be able to say embarrassing things about me on this blog.  Likewise if they compromise my bank account, though that would of course be bad for other reasons.


If you buy that, then you should make sure to use strong unique passwords and unique security questions for your bank accounts, your email accounts and your major social accounts, and use better security than that when it's available.  How much to worry about other accounts depends on how closely they're tied to the accounts that matter.  For example, if your city's online parking ticket paying site doesn't remember credit card numbers or your nefarious history of overparking, you probably don't care as much about security there.

Tuesday, April 26, 2011

"Thank you for your business"

The book is The Thank You Economy, by Gary Vaynerchuk.  The thesis is that, thanks to social media, business is returning to its mom-and-pop roots, in that personal customer service is once again becoming important.  I ran across the book listening to an interview with Vaynerchuk on NPR.

I'm of two minds about this:

Mind 1: Hmm ... it's all different now, is it?  Is business, in fact, paying more attention to individual customers?  Did it really stop?  How would you measure this?

Anecdotal evidence:  Today I took my car to the shop expecting a hefty amount of deferred maintenance because, well, it had been a while.  Instead, they explained what it really needed, did that, offered to fix a couple of minor problems that had been bugging me for years, which I had them go ahead and do, and sent me on my way for a modest sum.  These were the same folks who last year quickly and efficiently diagnosed and fixed a problem that the dealer I called had had no clue about, which is why I came back in the first place.

Are they on Facebook?  No.  Can I follow them on Twitter? No.  Do they provide no-nonsense service at a reasonable price?  Absolutely.  Do they have all the business they can handle?  Judging by the parking lot and the steady stream of customers, I'm guessing so.  Are they run essentially the same way they would have been 50 years ago?  Quite likely.

Mind 2:  Well, I've got to be a fan of someone who titles the first chapter of his book "How Everything Has Changed, Except Human Nature", and anyone pushing for good old-fashioned customer service is OK in my book.  Rather than focus on what historical trends might or might not have been, another take is that the modern web offers tools that let good businesspeople serve their customers better, even if those customers are across the country or the world.  In that case, he's got a point, and probably a lot of useful experience and tips to share.

Mind, Vaynerchuk's own site makes the less modest claim that the "Thank you economy" is "the most important shift in culture businesses have seen," but then, he's got a book to sell.

Thursday, April 29, 2010

E-commerce in China

Browsing The Economist, I ran across an interesting article exploring, um, economics of all things. In particular, the economics of online retailing in China. Key points:
  • China provides a particularly good environment for online retailing because delivery of goods is unusually cheap and storefronts are unusually expensive, at least in relative terms.
  • Online retailing couldn't take off without widespread internet access (of course), but the other sticking point was the lack of a trusted, home-grown payment system. "Just use PayPal" wasn't an option.
  • Online retailing favors well-established brands, including Western brands, which would not necessarily be favored in the brick-and-mortar world.
  • Just as has happened elsewhere, physical retailers can be undercut by their own online prices. People come into the store to take a look, then buy online.
Once again, it's worth noting that the economic issues are in the driver's seat. Technology never gets far until the economic conditions are favorable. Only then (I claim, for the moment) does it begin to affect the economic conditions in turn.

Monday, March 16, 2009

Curses, foiled again!

Seen on an automated ticket site, right next to the captchas:
You do not have permission to access this website if you are using an automated program.
Oh no! Now I'll have to modify my automated ticket-poaching bot to scrape the page I'm hitting and look for text that says I can't use the site. And it gets worse. It's not safe to just look for those particular words. They might decide to change the message to something really scary, like "TOP SEEKRIT NO BOTS ALLOWED WE MEAN IT!" No, I'll need to put together something that can parse English text and figure out whether or not I'm permitted to poach tickets there. That's even harder than cracking captchas.

Damn you, evil ticket guardians!

Tuesday, January 20, 2009

Three mildly silly things

  1. I realize that if you're the US Post Office, you have to aim for a broad, sort of lowest-common-denominator target, but as I understand it a server can get some idea of what kind of screen resolution the agent on the other end has, and perhaps serve up a map a bit bigger than the one on this page.
  2. When you relinquish tickets on an online ticketing site -- you know, the kind that charges you several bucks in "because we can" fees, a.k.a. "convenience" fees -- to try for different ones, wouldn't be nice if they actually gave you different tickets the next time?
  3. Apparently some local TV stations have taken to broadcasting "live via broadband" low-grade video as part of their broadcast news. OK, I get it. The world of journalism is going to the web.dogs and you want to show that you're on board. But putting up 10 frames per second lo-res video with compression artifacts that make your reporter look like something DalĂ­ would have painted on a bad day is not going to make the best tech-savvy impression. One is reminded of (now Senator [or maybe not]) Al Franken's infamous "one-man mobile uplink".
Ah well. I suppose that's what makes the web the web.

Note: I'm not sure how best to attribute the Frankenphoto. The particular flickr image I used is on Ross Mayfield's photo stream, but I assume NBC has a dog in the fight as well.

Saturday, December 29, 2007

Radiohead: Just what is going on here?

A few months ago Radiohead put out its latest album, In Rainbows, in two formats. You could get a "discbox" with a vinyl pressing, bonus CD, album art, etc. for a fixed price, or you could just download the tracks as .mp3 files and throw whatever you wanted (or nothing) in the tip jar.

So what happened? Who paid what? Do we have a whole new paradigm for music sales? An interesting one-off experiment? An out-and-out boondoggle? All or none of the above?

It's hard to see In Rainbows as a whole new paradigm, if only because there are so many special circumstances. Radiohead is an established band with a loyal following and a formidable reputation. The band happened to be between record contracts for this album. The downloadable version was a companion to a more traditional offering. And Radiohead is Radiohead. What works for them might not work for anyone else.

In fact, it may not even have worked for them. Certainly the band saw the online release as a one-off. They are currently in negotiations with both record labels and iTunes, and the download offer has been discontinued (effective New Year's Eve).

Beyond that, the picture gets very muddy very quickly. One report, by Gigwise, claims downloads of at least 1.2 million copies of the album. How much did people pay? Those who know aren't talking, but one survey indicates an average of 4 pounds (about $8), with 1/3 of downloaders paying nothing. Another, hotly disputed by the band, suggests that 62% paid nothing and the average price across all downloads was $2.26.

So basically, we don't know how many copies were downloaded, how much people paid for them, whether the price paid changed over time, why there's a discrepancy between the two surveys, or much of anything else. Except that the band most likely pulled in millions of dollars for the downloads, some further amount for the discboxes, and expects further income from traditional distribution. That's not even counting the T-shirt sales. Not bad for a bunch of guys from Oxfordshire.

If the tip-jar/download approach is not obviously the future of music distribution, but it's not a massive flop either, what is it, and why is the band discontinuing it? Is it the tip of the iceberg, or an evolutionary dead end like the million dollar homepage?

My guess, and it's only a guess, is that the tip-jar model is not going to dominate, though it might not disappear entirely. Rapper Saul Williams is currently spinning a variation on this with a low-bandwidth version of his latest release. The hi-fi version is available for a $5 donation.

Why is the band discontinuing the offer? My recollection from the original page is that it was never promised indefinitely in the first place. Most likely the band has gotten the good out of it. I would expect that people who care enough to pay also care enough to download early (which might explain some of the discrepancy between the two surveys). The band also seems not to have burned its bridges with traditional distribution channels, and continuing the "It's up to you" offer would only muddy the waters there.

Thursday, October 11, 2007

Pumping data through the Hetch Hetchy Aqueduct

Paul Vixie made a very interesting speech to the Commonwealth Club in San Francisco last year. As it was aimed at a general audience, he started out with some familiar points. I'll repeat them here [with a couple of comments] because they lead up to the more interesting conclusions:
  • Cash flow is more important than cash. The word for the day is monetize: to extract cash flow from.
  • One's ability to monetize things in the physical world is governed by regulations, including anti-trust regulations, balancing the good of society against the good of the individual.
  • Owning a physical CD or book or such is ownership in the dictionary sense.
  • This is regulated by copyright law, a fair system which has made a lot of money for content creators while supplying a lot of content to people who might not have had it otherwise.
  • This doesn't work in the virtual world, where perfect copying is cheap.
  • In the case of music, this is mostly a concern to the major labels and their artists. Smaller artists give away music digitally to promote concerts and sell T-shirts [see also Radiohead's latest release]
  • Big music, after trying to stop digital copying [actually, those lawsuits are still shaking out] has decided to try to make money off of digital music.
  • They do this by letting you listen to what you want but controlling the means of playing it. A typical software player reports your downloading, maybe shows pop-ups, and ties you to one of the commercial OS's -- and its upgrades. Again, the word is "monetize".
  • (For his part, Vixie just buys CDs and plays them on his Linux laptop. And respects copyrights.)
So far so good. But then he goes on:
  • This model of monetizing content applies to all content on computers, even content you produce yourself for your own use, that is, your email, text documents, etc. How does that work? It works because ...
  • Viruses, worms etc. are a major problem for computer users these days, a problem that many companies are trying to solve, that is, monetize.
  • Consumers just want their computers to work, but there's not actually any money to be had in solving that problem. A computer that Just Works is like a razor blade that never gets dull.
  • One part of the solution is to rent virus protection. In a fuller solution, OSs would ideally only run trusted applications registered with the OS vendor -- for a fee, of course. This is already how game boxes work.
  • Carry this over to the application world, and you end up renting the ability to access your own content, which is now stored in encrypted and/or proprietary form.
  • Fortunately, this is very difficult to pull off on current platforms. It would really require a whole new kind of hardware/software platform. Best to start small. Say, with music ...
And finally, Vixie draws a contrast between San Francisco's decision in the early twentieth century to build, operate and therefore control its own water supply, and its decision in the early twenty-first century not to build and operate its own wireless internet infrastructure, instead putting it out to bid.

In light of the points above, this may not be such a good idea. That doesn't mean that software vendors, record labels and so forth are evil, just that they're for-profit entities and must be expected to act as such.

Wednesday, October 3, 2007

OK, Computer

"Radiohead have made a record. So far, it is only available from this web site. You can pre-order it in these formats: Discbox and download."

With a plummy Oxbridge accent, a curiously garish homebrew website and a Thomas Pynchon reference included at no extra charge, Radiohead is doing its part to rock the digital content world. For a price of "It's up to you ... No really, it's up to you." you can have their latest, In Rainbows, straight from the band.

Or you can wait for your friends to get it and copy theirs. No really, it's up to you.

This isn't the first time a prominent act has bypassed the major labels (the artist formerly known as the artist formerly known as Prince comes to mind), but this one seems to be getting a fair bit of buzz. For example, Auntie says here that their server crashed from overwork.

It also says that most people are choosing to pay a reasonably normal price. I'm not surprised.

The general take I've seen on all this is that bands make most of their money from concert tickets and T-shirt sales anyway, so what's the big deal. Somewhere in the mix I hear record labels whistling in the dark, though interestingly Radiohead are currently said to be negotiating with their former label, Parlophone, and others for a new contract.

Wednesday, September 26, 2007

Proof of purchase

This is another popped-into-my-head, maybe-I've-seen-it-somewhere, don't-remember-where, someone's-probably-thought-of-it things.

If I have some digital content in my store (or on my disk, for that matter), it might be good if my particular copy had a nonce in it and the seller included a digitally signed receipt to the effect that "On this date this person bought this copy of this content for this amount from this seller".

Legitimate copies (backups, versions converted to other formats, etc.) would carry either the original proof of purchase (for verbatim copies) or a link to the original or at least the previous link in the chain. In effect, everything can have a provenance.

This doesn't keep me from stripping out the bits and giving an unsigned, de-nonced version to anyone and everyone for free. Airtight copy protection is an inherently hard if not impossible problem. What it does do, though, is cover me by saying hey, at least I paid for my copy.

Whether it's illegal to possess a copy without accompanying receipt is a separate issue. But chances are pirating in general will continue to be illegal, and having a convincing means of proving non-piracy ought to be worth something.

Conversely, having such a scheme in place makes content without clear provenance inherently suspect. Whether The Man can find out you have such, and if so, prove that you have it on purpose, is another separate issue.

Sunday, September 16, 2007

Classical music online

This article on classical music sales explores why classical music appears to be benefiting from the internet where everyone else seems to be struggling. It gives a few reasons, only one of which looks convincing for the long run:
  • Classical music is harder to pirate because it demands better sound quality and one generally buys it in bigger blocks. A high-fidelity recording of the Ring Cycle is a lot more bits than a 3-minute pop song in mp3 form. Classical listeners are also more interested in liner notes, biographies of the performers and such. Well, maybe, but people seem to have no trouble pirating DVDs.
  • Classical music requires more sophisticated cataloging. OK, so popular music players tend to assume all you care about is the performer and get confused when you have to talk about the composer as well, and they don't tend to recognize that a single piece can comprise several tracks. That's lame, but so what? This is not an overwhelming technical problem. It's a matter of picking a system and going with it. Libraries have been cataloging classical music by hand for decades or centuries depending on how you count, so that might be a good place to start. More to the point, several players have already had a go. This will not remain a differentiator for long.
  • Classical audiences are more suited to the "long tail". This I'll buy. Clasical listeners are more interested in, say, finding several performances of the same piece, or finding obscure composers, as opposed to buying what everyone else is buying. This means sellers can put out tons and tons of selections, the more the better, knowing that while only ten people might buy a given selection, someone will likely buy any given piece and in aggregate volume will be good. I don't think this is unique to the classical world, but it's not what's shifting millions of units at the top of the charts.
The main point I want to make here is that the "defensive" technological points (that is, the first two), don't wash. Piracy can't be lower for classical music because it's harder. It has to be lower for other reasons.

You could read this two ways:
  1. Once classical listeners figure out they can pirate, the game is up.
  2. In some markets, there is less desire and/or incentive to pirate.
I personally doubt that classical listeners are less technically savvy than everyone else (and the article claims the opposite). That makes understanding (2) interesting and important.

Friday, September 7, 2007

The Million Dollar Homepage

I'm sure everyone remembers this one -- it was only a couple of years ago and got tons of buzz -- but what an interesting tale. It's high on my (notional) list of neat hacks, social/business category.

First, Alex Tew is looking for ways to pay his tuition and decides to follow Mae West's "million men with a dollar" approach, selling off a 1000x1000 pixel image on milliondollarhomepage.com for $1/pixel, in 10x10 pixel blocks. With your block you also get a hover and a link to the site of your choice. Once you buy it, you can't change it, so choose carefully, grasshopper.

The 10x10 minimum was because a single pixel would be hard to click on and the resulting page would look "ghastly". But if you consider the net effect of hundreds of completely unrelated parties each trying to make a small block of pixels as attention-getting as possible ... well, "garish" doesn't begin to describe it. If you mashed up Liberace, Elton John and Bootsy Collins and ran the result through a blender you might be in the neighborhood. So I'll go with "ghastly" on this one.

As soon as word starts to get out on this "You've got to be joking ... no, it's serious ... why didn't I think of that?" idea, traffic goes through the roof. At one point the page is #127 on Alexa. Naturally, everyone wants to be part of the action.

Then it gets interesting. Someone buys up a largish group of adjacent blocks and rents out the sites behind them. Makes perfect sense. Copycats spring up, offering lower rates, whizzier features or both. Some even advertise on the page itself. A new term, "pixel advertising" is coined. Are we seeing the birth of a whole new business model here? Dare we say, a whole new economy?

Well, no. The original home page accomplishes its task admirably. All million pixels are snapped up quickly (I dithered over buying a block myself but couldn't think of anything worth $100 to put on it. Do I regret that? Not really.) The final 1000 pixels fetch $38,100 on EBay. Well done, Alex!

The copycats? Not so much. Even Tew's own offshoot, Pixelotto, is way undersubscribed at about 75,000 pixels sold and looks very unlikely to sell out before its self-imposed December 2007 deadline. Pixels1.com, which advertised on the M$HP itself, selling pixels for a penny with animation allowed, is even sparser yet. Another site, onecentads.com, is about half full. That's about $5000, less $900 for a 30x30 ad on M$HP. Its image is still there but doesn't appear to be clickable.

None of this seems surprising. The original M$HP got all kinds of traffic because it was newsworthy. That traffic lasted as long as it remained newsworthy, which was approximately until the last pixel sold. Then, poof. Old news, no traffic, or at least not a lot of paying traffic. People still visit the page itself from time to time, but I doubt many click through to the advertisers. I expect even fewer click through to the copycats (at least one appears to have disappeared completely), much less their advertisers.

If you managed to buy in early you probably got a good jolt of traffic, but you were probably just expecting to own a piece of an internet time capsule. That was all the site ever promised, after all. If you bought in late, you were probably expecting tons of traffic, but you ended up owning a piece of an internet time capsule.

Caveat emptor.

Thursday, August 23, 2007

E-Tickets and copy protection

(Back in the day, back before my day, "e-ticket" meant the best rides at Disneyland -- or maybe the Pasadena Freeway. I forget.)

Two questions come to mind about buying tickets to a events online:
  • Do they have to call the because-we-can and the because-the-venue-can fees "convenience charges"? Just exactly whose convenience are we talking about here?
  • Copy protection always fails. Why doesn't that matter here?
I can't answer the first one, but the second one is easy. You can make as may copies of an electronic ticket as you want. Knock yourself out. All you're really doing is copying a number. But you can only use that number once.

It says so right on the ticket, something like "This ticket may only be scanned once." If someone gets hold of one of the copies you've made and they get to the gate first, you're out of luck. Sorry, that ticket, meaning the magic number and not the piece of paper it's on, has already been used.

That's interesting, actually. You can make as many copies as you want, but you don't want to make any more than you have to. Enforcement is by incentive, not prohibition. This is a bit different from airline tickets, which are tied to an individual so that the would-be ticket thief will also need to forge your ID. I remember being a bit surprised that I didn't have to show ID to use an e-ticket to a show.

The underlying principle is that copy protection exists in the physical world. Things can only be in one place at a time and a particular event only happens once. To limit copy protection in the virtual world, you have to tie your virtual object to something the physical world, either an object or an event.

Copy protection based on objects has a long history. It worked fine when copying was physically difficult. Printing a book ties the virtual object (the contents of the book) to physical ink on a physical page. For centuries this was something most people couldn't easily do. Even with a photocopier, it's not something most people could do very cheaply or easily.

Since this approach worked so well it's no surprise that a lot of early copy protection schemes tried to emulate it. I remember writing code to talk to a dongle that hung off the printer port of a PC every so often to make sure the thing was still there and shut down the application if it wasn't.

The dongle itself was (according to its manufacturer) based on strong encryption, so you weren't going to be able to make a working copy of the dongle for your friend without factoring some infeasible-to-factor numbers. But I could never figure out why you'd have to.

The tie between the virtual object (the app) and the physical one (the dongle) was inherently weak. It couldn't be too hard for someone to figure out what part of the code talked to the dongle and replace it with something that only pretended to.

I remember spending quite a bit of time trying to design dodges like putting the dongle-handling code in some encrypted dynamic module, but it never took long to figure out a way around that, too. I'm pretty sure I later ran across papers in the literature saying the same thing more rigorously, and evidently the market came to the same conclusion. You don't see dongles anymore.

The same basic story has played out repeatedly. CDs worked fine until everyone had a CD burner (so copying the CD was easy) or an MP3 player (cutting the virtual/physical tie so you didn't need a CD player to hear a song). DVDs are more or less in the same boat now (and I'm not even talking about CSS).

The iPod effectively tried to tie iTunes songs to the player, but Apple's heart was never really in it. If nothing else you could burn songs to CD and re-rip them for your favorite player (so much for CDs as a copy-protection mechanism!). Certain recent operating systems appear to try to tie playback to physical artifacts like MAC addresses, but at this point I'm thinking I've seen this movie before and I know how it ends.

On the other hand, tying virtual objects to events seems to fare rather better. E-tickets work fine and rake in tons of money in because-we-can fees. Smartcard-based authentication systems are a variation of the same theme. A particular magic number will only flash on the display once and the server knows when that will happen.

I'm not sure how broadly this applies, though. In both the cases above the virtual object is the key to something physical of interest. It's not the object of interest itself. If it's the (virtual) content that's of interest, it's not clear that the tie to the physical world can ever be ironclad.

I was about to cite live broadcasting as an example, but this really depends on control of the broadcast mechanism. There's no technical reason I couldn't take the picture on my TV screen and stream it to all my friends and have a big virtual pay-per-view party. I personally don't have the bandwidth for such things, not to mention it being illegal, but the bandwidth will be there sooner or later and illegality won't deter everyone.

Other models are on even shakier technical ground. Producing an advertising-free public copy of a particular news source or private database is not a problem technically. It's an interesting question why it doesn't happen more.

Is it because The Man can come after someone who put up such a site (and why put it up unless lots of people will find out about it)? Is it because people don't like breaking the law? Is it because most people intuitively understand that if writers can't make money there won't be any content to steal? Or is it maybe because people just don't mind ads that much and it's not worth trying to pirate the content?

My guess is that it's a combination of all of those factors. It has to be something. Technology is not going to protect content. For most mass-market applications "strong" copy protection, where the virtual/physical tie is inherently strong and does not depend on control of some particular mechanism, seems doomed from the beginning.

That leaves a web (if you will) of legal and social constructs. Same as makes the rest of the world go round.